Latest CVE Feed
-
2.5
LOWCVE-2017-1211
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled. IBM X-Force ID: 123851.... Read more
Affected Products : daeja_viewone- EPSS Score: %0.04
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-12094
An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an access point reachable by the devi... Read more
- EPSS Score: %0.32
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1209
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr... Read more
Affected Products : daeja_viewone- EPSS Score: %0.18
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12071
Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.... Read more
Affected Products : photo_station- EPSS Score: %0.34
- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1182
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.... Read more
Affected Products : tivoli_monitoring- EPSS Score: %10.76
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1180
The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they did not have access to. IBM Reference #: 2001084.... Read more
Affected Products : tririga_application_platform- EPSS Score: %0.19
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-1176
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299.... Read more
- EPSS Score: %0.05
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11748
VIT Spider Player 2.5.3 has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll, olepro32.dll, dsound.dll, or AUDIOSES.dll file.... Read more
Affected Products : spider_player- EPSS Score: %0.24
- Published: Jul. 30, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-11725
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.... Read more
Affected Products : secret_server- EPSS Score: %0.16
- Published: Jul. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11675
The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP code by placing that code into an invalid array index of... Read more
Affected Products : zen_cart- EPSS Score: %0.72
- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-11657
Dashlane might allow local users to gain privileges by placing a Trojan horse WINHTTP.dll in the %APPDATA%\Dashlane directory.... Read more
Affected Products : dashlane- EPSS Score: %0.12
- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1161
IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitra... Read more
Affected Products : api_connect- EPSS Score: %0.38
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-0781
Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors.... Read more
Affected Products : zenworks_configuration_management- EPSS Score: %5.57
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11586
dayrui FineCms 5.0.9 has URL Redirector Abuse via the url parameter in a sync action, related to controllers/Weixin.php.... Read more
Affected Products : finecms- EPSS Score: %6.57
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11581
dayrui FineCms 5.0.9 has Cross Site Scripting (XSS) in admin/Login.php via a payload in the username field that does not begin with a '<' character.... Read more
Affected Products : finecms- EPSS Score: %0.24
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11567
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to ... Read more
Affected Products : mongoose_embedded_web_server_library- EPSS Score: %0.36
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11467
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.... Read more
Affected Products : orientdb- EPSS Score: %74.86
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11441
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.... Read more
Affected Products : whm- EPSS Score: %0.29
- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1143
IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive informat... Read more
Affected Products : kenexa_lcms_premier- EPSS Score: %0.14
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11381
A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.... Read more
Affected Products : deep_discovery_director- EPSS Score: %18.47
- Published: Aug. 01, 2017
- Modified: Apr. 20, 2025